<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>SSO with ADFS, forms login with ADSF Proxy</title>
  <link rel="alternate" href="http://developer.cisco.com/c/message_boards/find_thread?p_l_id=&amp;threadId=5891171" />
  <subtitle>SSO with ADFS, forms login with ADSF Proxy</subtitle>
  <id>http://developer.cisco.com/c/message_boards/find_thread?p_l_id=&amp;threadId=5891171</id>
  <updated>2013-05-21T04:03:24Z</updated>
  <dc:date>2013-05-21T04:03:24Z</dc:date>
  <entry>
    <title>RE: SSO with ADFS, forms login with ADSF Proxy</title>
    <link rel="alternate" href="http://developer.cisco.com/c/message_boards/find_message?p_l_id=&amp;messageId=5898672" />
    <author>
      <name>Rahul Patel</name>
    </author>
    <id>http://developer.cisco.com/c/message_boards/find_message?p_l_id=&amp;messageId=5898672</id>
    <updated>2012-06-20T21:08:47Z</updated>
    <published>2012-06-20T21:06:16Z</published>
    <summary type="html">Hello Kingsley,

I replaced urn:federation:authentication:windows;urn:oasis:names:tc:SAML:2.0:ac:classes:Password with  urn:federation:authentication:windows;urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport and that did the trick.  
 
OK, when i save this, its cutting off the end... So, you might have given me the right info... but, I needed the ProtectedTransport in the end.
 
Thank you for your help for getting this to work.

Rahul</summary>
    <dc:creator>Rahul Patel</dc:creator>
    <dc:date>2012-06-20T21:06:16Z</dc:date>
  </entry>
  <entry>
    <title>RE: SSO with ADFS, forms login with ADSF Proxy</title>
    <link rel="alternate" href="http://developer.cisco.com/c/message_boards/find_message?p_l_id=&amp;messageId=5898577" />
    <author>
      <name>Rahul Patel</name>
    </author>
    <id>http://developer.cisco.com/c/message_boards/find_message?p_l_id=&amp;messageId=5898577</id>
    <updated>2012-06-20T20:49:46Z</updated>
    <published>2012-06-20T20:49:46Z</published>
    <summary type="html">Hello Kingsley,

Thank you for your suggestion.  I am not sure what to use for the outside users.  But, I was told that, this setup is not supported and that I should post it here and someone will help.  :-)

I did try your suggestion and I got prompted for a user and password, and got a SAML assertion error.

Is there anywhere there is documentation or suggestion on what to try for the AuthnContextClassRefs on the WebEx site admin page?

Thank you,
Rahul</summary>
    <dc:creator>Rahul Patel</dc:creator>
    <dc:date>2012-06-20T20:49:46Z</dc:date>
  </entry>
  <entry>
    <title>RE: SSO with ADFS, forms login with ADSF Proxy</title>
    <link rel="alternate" href="http://developer.cisco.com/c/message_boards/find_message?p_l_id=&amp;messageId=5891195" />
    <author>
      <name>Kingsley Lewis</name>
    </author>
    <id>http://developer.cisco.com/c/message_boards/find_message?p_l_id=&amp;messageId=5891195</id>
    <updated>2012-06-19T16:09:02Z</updated>
    <published>2012-06-19T16:09:02Z</published>
    <summary type="html">Hi Rahul,

The most likely reason for this is the AuthnContextClassRef coming from the outside users is different then the one from inside users.  
To work around this problem WebEx will allow you to set multiple AuthnContextClassRefs on the WebEx site admin page that are separated by a semicolon It would look something like this 

urn:federation:authentication:windows;urn:oasis:names:tc:SAML:2.0:ac:classes:Password

if you do not know what the value is for external users, I would try the above suggestion first.  If it still fails then you will need to contact technical support and provide the assertion ADFS is generating for an outside user.

Thank you
-Kingsley Lewis</summary>
    <dc:creator>Kingsley Lewis</dc:creator>
    <dc:date>2012-06-19T16:09:02Z</dc:date>
  </entry>
  <entry>
    <title>SSO with ADFS, forms login with ADSF Proxy</title>
    <link rel="alternate" href="http://developer.cisco.com/c/message_boards/find_message?p_l_id=&amp;messageId=5891170" />
    <author>
      <name>Rahul Patel</name>
    </author>
    <id>http://developer.cisco.com/c/message_boards/find_message?p_l_id=&amp;messageId=5891170</id>
    <updated>2012-06-19T16:03:22Z</updated>
    <published>2012-06-19T16:03:22Z</published>
    <summary type="html">Hello,
Followed the ADFS setup guide that was emailed to us and we were able to get SSO work and Auto Account Create work when we are internal on our network.  We setup an ADFS proxy server in the DMZ, so that, when using your computer from home or using a mobile device, it would hit the ADFS proxy and prompt for a username and password.  When we click on Host log in, it does prompt for username and password, but when I type my username and password, I get an "User Authentication Failed":  Reason:  Invalid SAML Assertion (13).
 
Does anyone have this working in their environment?  Anything you need from to get this corrected, please let me know.
 
Thank you,
Rahul Patel</summary>
    <dc:creator>Rahul Patel</dc:creator>
    <dc:date>2012-06-19T16:03:22Z</dc:date>
  </entry>
</feed>

